[BACK]Return to 75.html CVS log [TXT][DIR] Up to [local] / www

File: [local] / www / 75.html (download) (as text)

Revision 1.2, Sun Mar 3 20:55:54 2024 UTC (2 months, 3 weeks ago) by benno
Branch: MAIN
Changes since 1.1: +40 -2 lines

add rpki-client changes

<!doctype html>
<html lang=en id=release>
<head>
<meta charset=utf-8>

<title>OpenBSD 7.5</title>
<meta name="description" content="OpenBSD 7.5">
<meta name="viewport" content="width=device-width, initial-scale=1">
<link rel="stylesheet" type="text/css" href="openbsd.css">
<link rel="canonical" href="https://www.openbsd.org/75.html">
</head><body>
<h2 id=OpenBSD>
<a href="index.html">
<i>Open</i><b>BSD</b></a>
7.5
</h2>

<table>
<tr>
<td>
<a href="images/XXX.jpg">
<img width="227" height="303" src="images/XXX-s.gif" alt="XXX"></a>
<td>
Released XXXMONTH DAY, 2024. (56th OpenBSD release)<br>
Copyright 1997-2024, Theo de Raadt.<br>
<br>
Artwork by XXX.
<br>
<ul>
<li>See the information on <a href="ftp.html">the FTP page</a> for
    a list of mirror machines.
<li>Go to the <code class=reldir>pub/OpenBSD/7.5/</code> directory on
    one of the mirror sites.
<li>Have a look at <a href="errata75.html">the 7.5 errata page</a> for a list
    of bugs and workarounds.
<li>See a <a href="plus75.html">detailed log of changes</a> between the
    7.4 and 7.5 releases.
<p>
<li><a href="https://man.openbsd.org/signify.1">signify(1)</a>
    pubkeys for this release:<p>

<table class=signify>
<tr><td>
openbsd-75-base.pub:
<td>
<a href="https://ftp.openbsd.org/pub/OpenBSD/7.5/openbsd-75-base.pub">
RWRGj1pRpprAfgeF/rgld4ubduChLvTkigA1Zj7WLDsVA4qfYSWOEI8q
</a><tr><td>
openbsd-75-fw.pub:
<td>
RWQ6EsXr4NMYvyLICug3dLHfmbpXlVasF1jbt3GVNQsosgB5+PgaufBu
<tr><td>
openbsd-75-pkg.pub:
<td>
RWS/sEFDvf+rjUmS1WROzxH05pB1kB7JRRq76DUGUhCE0Ks8AdpjP5pD
<tr><td>
openbsd-75-syspatch.pub:
<td>
RWRAAZC5WcFgn+8b5msDR+yDVCx4ziLaSQI2sy7e4GFY42nFW9p7mP2t
</table>
</ul>
<p>
All applicable copyrights and credits are in the src.tar.gz,
sys.tar.gz, xenocara.tar.gz, ports.tar.gz files, or in the
files fetched via <code>ports.tar.gz</code>.
</table>

<hr>

<section id=new>
<h3>What's New</h3>
<p>
This is a partial list of new features and systems included in OpenBSD 7.5.
For a comprehensive list, see the <a href="plus75.html">changelog</a> leading <!-- plus? XXX -->
to 7.5.

<ul>

<!--
<li>New/extended platforms:
  <ul>
  <li>...
  </ul>
-->

<li>Various kernel improvements:
  <ul>
  <li>...
  </ul>

<li>SMP Improvements
  <ul>
  <li>...
  </ul>

<li>Direct Rendering Manager and graphics drivers
  <ul>
  <li>...
  </ul>

<li>VMM/VMD improvements
  <ul>
  <li>...
  </ul>

<li>Various new userland features:
  <ul>
  <li>...
  </ul>

<li>Various bugfixes and tweaks in userland:
  <ul>
  <li>...
  </ul>

<li>Improved hardware support and driver bugfixes, including:
  <ul>
<!-- new drivers -->
  <li>...

<!-- other -->
  <li>...
  </ul>

<li>New or improved network hardware support:
  <ul>
  <li>...
  </ul>

<li>Added or improved wireless network drivers:
  <ul>
  <li>...
  </ul>

<li>IEEE 802.11 wireless stack improvements and bugfixes:
  <ul>
  <li>...
  </ul>

<li>Installer, upgrade and bootloader improvements:
  <ul>
  <li>...
  </ul>

<li>Security improvements:
  <ul>
  <li>...
  </ul>

<li>Changes in the network stack:
  <ul>
  <li>...
  </ul>

<li>The following changes were made to the <a
	href="https://man.openbsd.org/pf.4">pf(4)</a> firewall:
  <ul>
  <li>...
  </ul>


<li>Routing daemons and other userland network improvements:
  <ul>

  <li>IPsec support was improved:
  <ul>
	<li>...
  </ul>

  <li>In <a href="https://man.openbsd.org/bgpd.8">bgpd(8)</a>,
  <ul>
	<li>...
  </ul>

  <li><a href="https://man.openbsd.org/rpki-client.8">rpki-client(8)</a> saw these and more changes:
  <ul>
	<li>Add ability to constrain an RPKI Trust Anchor's effective signing
	authority to a limited set of Internet numbers. This allows Relying
	Parties to enjoy the potential benefits of assuming trust, but within
	a bounded scope.
	<li>Following a 'failed fetch' (described in RFC 9286), emit a warning and
	continue with a previously cached Manifest file.
	<li>Emit a warning when the remote repository presents a Manifest with an
	unexpected manifestNumber.
	<li>Improved CRL extension checking.
	<li>Experimental support for the P-256 signature algorithm.
	<!-- 8.8. -->
	<li>A failed manifest fetch could result in a NULL pointer dereference or
	a use after free.
	<li>Reject non-conforming RRDP delta elements that contain neither publish
	nor a withdraw element and fall back to the RRDP snapshot.
	<li>Refactoring and minor bug fixes in the warning display functions.
	<!-- 8.9 -->
	<li>The handling of manifests fetched via rsync or RRDP was reworked to
	fully conform to RFC 9286.
	<li>Fix a race condition between closing an idle connection and scheduling a
	new request on it.
	<li>The evaluation time specified with -P now also applies to trust anchor
	certificates.
	<li>Check that the entire CMS eContent was consumed. Previously, trailing
	data would be silently discarded on deserialization of products.
	<li>In file mode do not consider overclaiming intermediate CA certificates
	as invalid.  OAA warning is still issued.
	<li>Print the revocation time of certificates in file mode.
	<li>Be more careful when converting OpenSSL numeric identifiers (NIDs)
	to strings.
	<!-- 9.0 -->
	<li>Added support for RPKI Signed Prefix Lists.
	<li>Added an -x flag to opt into parsing and evaluation of file types that are
	still considered experimental.
	<li>Added a metric to track the number of new files that were moved to the
	validated cache.
	<li>Ensure that the FileAndHashes list in a Manifest contains no duplicate
	file names and no duplicate hashes.
  </ul>

  <li>In <a href="https://man.openbsd.org/smtpd.8">smtpd(8)</a>,
  <ul>
	<li>...
  </ul>

  <li>Many other changes in various network programs and libraries:
  <ul>
	<li>...
  </ul>
  </ul>

<li><a href="https://man.openbsd.org/tmux.1">tmux(1)</a> improvements and bug fixes:
  <ul>
  <li>...
  </ul>

<li>LibreSSL version 3.8.x
  <ul>
  <li>Security fixes
    <ul>
    <li>...
    </ul>
  <li>Portable changes
    <ul>
    <li>...
    </ul>
  <li>New features
    <ul>
    <li>...
    </ul>
  <li>Compatibility changes
    <ul>
    <li>...
    </ul>
  <li>Internal improvements
    <ul>
    <li>...
    </ul>
  <li>Bug fixes
    <ul>
    <li>...
    </ul>
  <li>Documentation improvements
    <ul>
    <li>...
    </ul>
  <li>Testing and Proactive Security
    <ul>
    <li>...
    </ul>
  </ul>

<li>OpenSSH 9.x and OpenSSH 9.x
  <ul>
  <li>Potentially incompatible changes
    <ul>
    <li>...
    </ul>
  <li>New features
    <ul>
    <li>...
    </ul>
  <li>Bugfixes
    <ul>
    <li>...
    </ul>
  </ul>

<li>Ports and packages:
  <p>Many pre-built packages for each architecture:
  <!-- number of FTP packages minus SHA256, SHA256.sig, index.txt -->
  <ul style="column-count: 3">
    <li>aarch64:    XXX
    <li>amd64:      XXX
    <li>arm:        XXX
    <li>i386:       XXX
    <li>mips64:     XXX
    <li>powerpc:    XXX
    <li>powerpc64:  XXX
    <li>riscv64:    XXX
    <li>sparc64:    XXX
  </ul>

  <p>Some highlights:
  <ul style="column-count: 3"><!-- XXX all need to be checked/updated 2024-03-02 -->
    <li>Asterisk 16.30.1, 18.19.0 and 20.4.0
    <li>Audacity 3.3.3
    <li>CMake 3.27.5
    <li>Chromium 117.0.5938.149
    <li>Emacs 29.1
    <li>FFmpeg 4.4.4
    <li>GCC 8.4.0 and 11.2.0
    <li>GHC 9.2.7
    <li>GNOME 44
    <li>Go 1.21.1
    <li>JDK 8u382, 11.0.20 and 17.0.8
    <li>KDE Applications 23.08.0
    <li>KDE Frameworks 5.110.0
    <li>Krita 5.1.5
    <li>LLVM/Clang 13.0.0 and 16.0.6
    <li>LibreOffice 7.6.2.1
    <li>Lua 5.1.5, 5.2.4, 5.3.6 and 5.4.6
    <li>MariaDB 10.9.6
    <li>Mono 6.12.0.199
    <li>Mozilla Firefox 118.0.1 and ESR 115.3.1
    <li>Mozilla Thunderbird 115.3.1
    <li>Mutt 2.2.12 and NeoMutt 20230517
    <li>Node.js 18.18.0
    <li>OCaml 4.12.1
    <li>OpenLDAP 2.6.6
    <li>PHP 7.5.33, 8.0.30, 8.1.24 and 8.2.11
    <li>Postfix 3.7.3
    <li>PostgreSQL 15.4
    <li>Python 2.7.18, 3.9.18, 3.10.13 and 3.11.5
    <li>Qt 5.15.10 and 6.5.2
    <li>R 4.2.3
    <li>Ruby 3.0.6, 3.1.4 and 3.2.2
    <li>Rust 1.72.1
    <li>SQLite 3.42.0
    <li>Shotcut 23.07.29
    <li>Sudo 1.9.14.2
    <li>Suricata 6.0.12
    <li>Tcl/Tk 8.5.19 and 8.6.13
    <li>TeX Live 2022
    <li>Vim 9.0.1897 and Neovim 0.9.1
    <li>Xfce 4.18
  </ul>
  <p>

<li>As usual, steady improvements in manual pages and other documentation.

<li>The system includes the following major components from outside suppliers:
  <ul><!-- XXX all need to be checked/updated 2024-03-02 -->
    <li>Xenocara (based on X.Org 7.7 with xserver 21.1.8 + patches,
        freetype 2.13.0, fontconfig 2.14.2, Mesa 22.3.7, xterm 378,
        xkeyboard-config 2.20, fonttosfnt 1.2.2 and more)
    <li>LLVM/Clang 13.0.0 (+ patches)
    <li>GCC 4.2.1 (+ patches) and 3.3.6 (+ patches)
    <li>Perl 5.36.1 (+ patches)
    <li>NSD 4.7.0
    <li>Unbound 1.18.0
    <li>Ncurses 5.7
    <li>Binutils 2.17 (+ patches)
    <li>Gdb 6.3 (+ patches)
    <li>Awk September 12, 2023
    <li>Expat 2.5.0
    <li>zlib 1.3 (+ patches)
  </ul>

</ul>
</section>

<hr>

<section id=install>
<h3>How to install</h3>
<p>
Please refer to the following files on the mirror site for
extensive details on how to install OpenBSD 7.5 on your machine:

<ul>
<li><a href="https://ftp.openbsd.org/pub/OpenBSD/7.5/alpha/INSTALL.alpha">
	.../OpenBSD/7.5/alpha/INSTALL.alpha</a>
<li><a href="https://ftp.openbsd.org/pub/OpenBSD/7.5/amd64/INSTALL.amd64">
	.../OpenBSD/7.5/amd64/INSTALL.amd64</a>
<li><a href="https://ftp.openbsd.org/pub/OpenBSD/7.5/arm64/INSTALL.arm64">
	.../OpenBSD/7.5/arm64/INSTALL.arm64</a>
<li><a href="https://ftp.openbsd.org/pub/OpenBSD/7.5/armv7/INSTALL.armv7">
	.../OpenBSD/7.5/armv7/INSTALL.armv7</a>
<li><a href="https://ftp.openbsd.org/pub/OpenBSD/7.5/hppa/INSTALL.hppa">
	.../OpenBSD/7.5/hppa/INSTALL.hppa</a>
<li><a href="https://ftp.openbsd.org/pub/OpenBSD/7.5/i386/INSTALL.i386">
	.../OpenBSD/7.5/i386/INSTALL.i386</a>
<li><a href="https://ftp.openbsd.org/pub/OpenBSD/7.5/landisk/INSTALL.landisk">
	.../OpenBSD/7.5/landisk/INSTALL.landisk</a>
<li><a href="https://ftp.openbsd.org/pub/OpenBSD/7.5/loongson/INSTALL.loongson">
	.../OpenBSD/7.5/loongson/INSTALL.loongson</a>
<li><a href="https://ftp.openbsd.org/pub/OpenBSD/7.5/luna88k/INSTALL.luna88k">
	.../OpenBSD/7.5/luna88k/INSTALL.luna88k</a>
<li><a href="https://ftp.openbsd.org/pub/OpenBSD/7.5/macppc/INSTALL.macppc">
	.../OpenBSD/7.5/macppc/INSTALL.macppc</a>
<li><a href="https://ftp.openbsd.org/pub/OpenBSD/7.5/octeon/INSTALL.octeon">
	.../OpenBSD/7.5/octeon/INSTALL.octeon</a>
<li><a href="https://ftp.openbsd.org/pub/OpenBSD/7.5/powerpc64/INSTALL.powerpc64">
	.../OpenBSD/7.5/powerpc64/INSTALL.powerpc64</a>
<li><a href="https://ftp.openbsd.org/pub/OpenBSD/7.5/riscv64/INSTALL.riscv64">
	.../OpenBSD/7.5/riscv64/INSTALL.riscv64</a>
<li><a href="https://ftp.openbsd.org/pub/OpenBSD/7.5/sparc64/INSTALL.sparc64">
	.../OpenBSD/7.5/sparc64/INSTALL.sparc64</a>
</ul>
</section>

<hr>

<section id=quickinstall>
<p>
Quick installer information for people familiar with OpenBSD, and the use of
the "<a href="https://man.openbsd.org/disklabel.8">disklabel</a> -E" command.
If you are at all confused when installing OpenBSD, read the relevant
INSTALL.* file as listed above!

<h3>OpenBSD/alpha:</h3>

<p>
If your machine can boot from CD, you can write <i>install75.iso</i> or
<i>cd75.iso</i> to a CD and boot from it.
Refer to INSTALL.alpha for more details.

<h3>OpenBSD/amd64:</h3>

<p>
If your machine can boot from CD, you can write <i>install75.iso</i> or
<i>cd75.iso</i> to a CD and boot from it.
You may need to adjust your BIOS options first.

<p>
If your machine can boot from USB, you can write <i>install75.img</i> or
<i>miniroot75.img</i> to a USB stick and boot from it.

<p>
If you can't boot from a CD, floppy disk, or USB,
you can install across the network using PXE as described in the included
INSTALL.amd64 document.

<p>
If you are planning to dual boot OpenBSD with another OS, you will need to
read INSTALL.amd64.

<h3>OpenBSD/arm64:</h3>

<p>
Write <i>install75.img</i> or <i>miniroot75.img</i> to a disk and boot from it
after connecting to the serial console.  Refer to INSTALL.arm64 for more
details.

<h3>OpenBSD/armv7:</h3>

<p>
Write a system specific miniroot to an SD card and boot from it after connecting
to the serial console.  Refer to INSTALL.armv7 for more details.

<h3>OpenBSD/hppa:</h3>

<p>
Boot over the network by following the instructions in INSTALL.hppa or the
<a href="hppa.html#install">hppa platform page</a>.

<h3>OpenBSD/i386:</h3>

<p>
If your machine can boot from CD, you can write <i>install75.iso</i> or
<i>cd75.iso</i> to a CD and boot from it.
You may need to adjust your BIOS options first.

<p>
If your machine can boot from USB, you can write <i>install75.img</i> or
<i>miniroot75.img</i> to a USB stick and boot from it.

<p>
If you can't boot from a CD, floppy disk, or USB,
you can install across the network using PXE as described in
the included INSTALL.i386 document.

<p>
If you are planning on dual booting OpenBSD with another OS, you will need to
read INSTALL.i386.

<h3>OpenBSD/landisk:</h3>

<p>
Write <i>miniroot75.img</i> to the start of the CF
or disk, and boot normally.

<h3>OpenBSD/loongson:</h3>

<p>
Write <i>miniroot75.img</i> to a USB stick and boot bsd.rd from it
or boot bsd.rd via tftp.
Refer to the instructions in INSTALL.loongson for more details.

<h3>OpenBSD/luna88k:</h3>

<p>
Copy 'boot' and 'bsd.rd' to a Mach or UniOS partition, and boot the bootloader
from the PROM, and then bsd.rd from the bootloader.
Refer to the instructions in INSTALL.luna88k for more details.

<h3>OpenBSD/macppc:</h3>

<p>
Burn the image from a mirror site to a CDROM, and power on your machine
while holding down the <i>C</i> key until the display turns on and
shows <i>OpenBSD/macppc boot</i>.

<p>
Alternatively, at the Open Firmware prompt, enter <i>boot cd:,ofwboot
/7.5/macppc/bsd.rd</i>

<h3>OpenBSD/octeon:</h3>

<p>
After connecting a serial port, boot bsd.rd over the network via DHCP/tftp.
Refer to the instructions in INSTALL.octeon for more details.

<h3>OpenBSD/powerpc64:</h3>

<p>
To install, write <i>install75.img</i> or <i>miniroot75.img</i> to a
USB stick, plug it into the machine and choose the <i>OpenBSD
install</i> menu item in Petitboot.
Refer to the instructions in INSTALL.powerpc64 for more details.

<h3>OpenBSD/riscv64:</h3>

<p>
To install, write <i>install75.img</i> or <i>miniroot75.img</i> to a
USB stick, and boot with that drive plugged in.
Make sure you also have the microSD card plugged in that shipped with the
HiFive Unmatched board.
Refer to the instructions in INSTALL.riscv64 for more details.

<h3>OpenBSD/sparc64:</h3>

<p>
Burn the image from a mirror site to a CDROM, boot from it, and type
<i>boot cdrom</i>.

<p>
If this doesn't work, or if you don't have a CDROM drive, you can write
<i>floppy75.img</i> or <i>floppyB75.img</i>
(depending on your machine) to a floppy and boot it with <i>boot
floppy</i>. Refer to INSTALL.sparc64 for details.

<p>
Make sure you use a properly formatted floppy with NO BAD BLOCKS or your install
will most likely fail.

<p>
You can also write <i>miniroot75.img</i> to the swap partition on
the disk and boot with <i>boot disk:b</i>.

<p>
If nothing works, you can boot over the network as described in INSTALL.sparc64.
</section>

<hr>

<section id=upgrade>
<h3>How to upgrade</h3>
<p>
If you already have an OpenBSD 7.4 system, and do not want to reinstall,
upgrade instructions and advice can be found in the
<a href="faq/upgrade75.html">Upgrade Guide</a>.
</section>

<hr>

<section id=sourcecode>
<h3>Notes about the source code</h3>
<p>
<code>src.tar.gz</code> contains a source archive starting at <code>/usr/src</code>.
This file contains everything you need except for the kernel sources,
which are in a separate archive.
To extract:
<blockquote><pre>
# <kbd>mkdir -p /usr/src</kbd>
# <kbd>cd /usr/src</kbd>
# <kbd>tar xvfz /tmp/src.tar.gz</kbd>
</pre></blockquote>
<p>
<code>sys.tar.gz</code> contains a source archive starting at <code>/usr/src/sys</code>.
This file contains all the kernel sources you need to rebuild kernels.
To extract:
<blockquote><pre>
# <kbd>mkdir -p /usr/src/sys</kbd>
# <kbd>cd /usr/src</kbd>
# <kbd>tar xvfz /tmp/sys.tar.gz</kbd>
</pre></blockquote>
<p>
Both of these trees are a regular CVS checkout.  Using these trees it
is possible to get a head-start on using the anoncvs servers as
described <a href="anoncvs.html">here</a>.
Using these files
results in a much faster initial CVS update than you could expect from
a fresh checkout of the full OpenBSD source tree.
</section>

<hr>

<section id=ports>
<h3>Ports Tree</h3>
<p>
A ports tree archive is also provided.  To extract:
<blockquote><pre>
# <kbd>cd /usr</kbd>
# <kbd>tar xvfz /tmp/ports.tar.gz</kbd>
</pre></blockquote>
<p>
Go read the <a href="faq/ports/index.html">ports</a> page
if you know nothing about ports
at this point.  This text is not a manual of how to use ports.
Rather, it is a set of notes meant to kickstart the user on the
OpenBSD ports system.
<p>
The <i>ports/</i> directory represents a CVS checkout of our ports.
As with our complete source tree, our ports tree is available via
<a href="anoncvs.html">AnonCVS</a>.
So, in order to keep up to date with the -stable branch, you must make
the <i>ports/</i> tree available on a read-write medium and update the tree
with a command like:
<blockquote><pre>
# <kbd>cd /usr/ports</kbd>
# <kbd>cvs -d anoncvs@server.openbsd.org:/cvs update -Pd -rOPENBSD_7_5</kbd>
</pre></blockquote>
<p>
[Of course, you must replace the server name here with a nearby anoncvs
server.]
<p>
Note that most ports are available as packages on our mirrors. Updated
ports for the 7.5 release will be made available if problems arise.
<p>
If you're interested in seeing a port added, would like to help out, or just
would like to know more, the mailing list
<a href="mail.html">ports@openbsd.org</a> is a good place to know.
</section>
</body>
</html>